Analytics
Informational
✕
Abnormal connections to a dormant host from a newly seen endpoint
The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network.
- Module:
- Platform Analytics
- Data source:
- Palo Alto Networks Firewall traffic Logs, XDR Agent
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Remote System Discovery (T1018)
Attacker's goals:
While probing the network, an attacker may discover dormant hosts. These inactive systems can then be used for lateral movement or privilege escalation.
Investigative actions:
Validate that the source is not a sanctioned port scanner. Check for suspicious artifacts in the endpoint profile.
- Test period:
- 6 Hours
- Deduplication:
- 1 Day
1 variation:
- Abnormal connections to a dormant host Low (parent: Informational)